QID 317278
Date Published: 2022-11-23
QID 317278: Cisco Firepower Management Center (FMC) Software Extensible Markup Language (XML) External Entity (XEE) Injection Vulnerability (cisco-sa-fmc-xxe-MzPC4bYd)
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information.
Affected Products
This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FMC Software.
6.1.0 prior to version 6.4.0.16
6.5.0 prior to version 6.6.7
6.7.0 prior to version 7.0.5
7.1.0 prior to version 7.2.0
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to read sensitive data that would normally not be revealed.
Customers are advised to refer to cisco-sa-fmc-xxe-MzPC4bYd for more information.
- cisco-sa-fmc-xxe-MzPC4bYd -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xxe-MzPC4bYd
CVEs related to QID 317278
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-fmc-xxe-MzPC4bYd |
|